VYPR
High severity7.5NVD Advisory· Published Jul 5, 2016· Updated May 6, 2026

CVE-2016-4953

CVE-2016-4953

Description

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.

Affected products

37
  • cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
    • cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:manager:2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:manager_proxy:2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:suse:openstack_cloud:5:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_desktop:12:sp1:*:*:*:*:*:*
  • Ntp/Ntp22 versions
    cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*range: >=4.2.0,<4.2.8
    • cpe:2.3:a:ntp:ntp:4.2.8:-:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p1-beta1:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p1-beta2:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p1-beta3:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p1-beta4:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p1-beta5:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p1-rc1:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p1-rc2:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p2:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p2-rc1:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p2-rc2:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p2-rc3:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p3:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p3-rc1:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p3-rc2:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p3-rc3:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p4:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p5:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p6:*:*:*:*:*:*
    • cpe:2.3:a:ntp:ntp:4.2.8:p7:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*+ 3 more
    • cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:ltss:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
    • cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_net_cp_443-1_opc_ua_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:tim_4r-ie_firmware:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:tim_4r-ie_dnp3_firmware:*:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

32

News mentions

0

No linked articles in our index yet.